US2023009167A1PendingUtilityA1
Post-connection client certificate authentication
Est. expiryDec 19, 2036(~10.4 yrs left)· nominal 20-yr term from priority
H04L 63/105H04L 63/101H04W 12/069H04L 63/0272H04L 63/0823H04L 63/0876H04L 63/20
64
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A network access control (NAC) device detects a connection of an endpoint device at a network switch coupled to a network and restricts access of the endpoint device to prevent the endpoint device from accessing resources of the network. The NAC device establishes a connection with the endpoint device, validates a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device and grants the endpoint device access to the resources of the network.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . (canceled)
2 . A system comprising:
a memory; and a processing device operatively coupled to the memory, the processing device to:
detect an initial coupling of an endpoint device at a network switch coupled to a network; and
in response to detecting the initial coupling of the endpoint device at the network switch, apply an access control list to restrict access of the endpoint device to the network through the network switch to prevent the endpoint device from accessing resources of the network.
establish a connection with the endpoint device;
validate a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device; and
in response to validating the client certificate corresponding to the endpoint device, update the access control list to grant the endpoint device access to the resources of the network.
3 . The system of claim 2 , wherein to restrict access of the endpoint device, the processing device to apply at least one of the access control list or a VLAN assignment to the network switch, the access control list to define which resources of the network the endpoint device can access.
4 . The system of claim 2 , wherein to establish the connection with the endpoint device, the processing device to receive a communication request from a network access control agent on the endpoint device.
5 . The system of claim 2 , wherein to establish the connection with the endpoint device, the processing device to monitor network traffic through the network switch and detect a presence of the endpoint device.
6 . The system of claim 2 , wherein the processing device further to validate a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device.
7 . The system of claim 2 , wherein the processing device further to grant the endpoint device access to the resources of the network.
8 . A method comprising:
detecting an initial coupling of a client device at a network switch coupled to a network; and in response to detecting the initial coupling of the client device to the network, setting access permissions for the client device to provide access to a network access control device through the network switch and to restrict the client device from accessing resources of the network through the network switch.
9 . The method of claim 8 , wherein setting access permissions for the client device comprises applying at least one of an access control list or a wireless role to an access control device in the network, the access control list to define which resources of the network the client device can access.
10 . The method of claim 8 , wherein establishing the connection between the network access control device and the client device comprises receiving a communication request from a network access control agent on the client device.
11 . The method of claim 8 , wherein establishing the connection between the network access control device and the client device comprises monitoring network traffic through an access control device in the network and detecting a presence of the client device.
12 . The method of claim 8 , further comprising authenticating the client device based on a client security token.
13 . The method of claim 8 , further comprising:
not restricting access of the client device to the resources of the network when the network access control device suffers a failure during authentication of the client device.
14 . A non-transitory computer readable storage medium storing instructions, which when executed, cause a processing device to:
detect an initial coupling of a computing device at a network switch of a network; and upon detecting of the initial coupling of the computing device at the network switch coupled to a network, apply an access control list to prevent the computing device from accessing any resources of the network through the network switch except a network access control device.
15 . The non-transitory computer readable storage medium of claim 14 , wherein to prevent the computing device from accessing any resources of the network except a network access control device, the processing device to apply at least one of the access control list or a virtual firewall to the network switch in the network, the access control list to define which resources of the network the computing device can access.
16 . The non-transitory computer readable storage medium of claim 14 , wherein the processing device further to establish a connection between the network access control device and the computing device.
17 . The non-transitory computer readable storage medium of claim 16 , wherein to establish the connection between the network access control device and the computing device, the processing device to monitor network traffic through the network switch in the network and detect a presence of the computing device.
18 . The non-transitory computer readable storage medium of claim 14 , wherein the processing device further to determine whether the computing device is an authorized computing device using the connection between the network access control device and the computing device.
19 . The non-transitory computer readable storage medium of claim 18 , wherein the processing device further to allow the computing device to access additional resources of the network when the computing device is determined to be the authorized computing device.
20 . The non-transitory computer readable storage medium of claim 14 , wherein instructions further cause the processing device to:
not restrict access of the computing device to the resources of the network when the network access control device suffers a failure during authentication of the computing device.Join the waitlist — get patent alerts
Track US2023009167A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.